Advisory
A note with CVSS 6.1 for component BC-MID-BUS was released by SAP on 11.11.2025. The correction/advisory 3662000 was described with "[CVE-2025-42893] Open Redirect vulnerability in SAP Business Connector" and affects the system type SAP Business Connector.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is open redirect within SAP Business Connector.
Risk specification
SAP Business Connector allows an unauthenticated attacker to craft a malicious URL that, when accessed by a victim, redirects them to an attacker-controlled site within an embedded frame, resulting in exposure to unauthorized actions.Solution
The application now validates redirect URLs to prevent unauthorized redirection to external sites.
